The information security management standard ISO 27001 and its code of practice ISO 27002 were updated in 2013. A new iteration of ISO 27002 was published in February 2022, and the revised version of ISO 27001, ISO/IEC 27001:2022, followed on 25 October 2022.
Wondering what the changes are? This article aims to provide you with the knowledge you require to understand the changes introduced in ISO 27001:2022 and ISO 27002:2022.
Here are the ten most common questions in regards to the updates to ISO 27001 & 27002, answered:
The ISO 27001 is a globally recognised standard for information security. It allows for your business to equip itself with a risk-based approach to information security that is internationally accepted as best practice.
One of the key ways it achieves this is through the introduction of an Information Security Management System (ISMS). An ISMS assists businesses in identifying, assessing, mitigating, and managing the risks involved in managing corporate information and assets. ISO 27002 is a set of guidelines or controls that are designed to help you introduce and implement ISMS best practices.
Achieving ISO 27001 certification proves to your customers and partners that your business is committed to achieving an international standard of information security. The certification helps increase your credibility and reputation amongst customers and is a huge differentiating factor amongst competitors.
The key difference between ISO 27001 and ISO 27002 is that, while you can earn ISO 27001 certification for your business, you cannot earn ISO 27002 certification. ISO 27001 is the main standard, whereas ISO 27002 is a supporting set of controls that exists to provide guidance and help you implement best security practices for ISO 27001 certification. They are companion standards in the same ISO/IEC 27000 family.
Lock Down Your Cybersecurity & Compliance
Protect, Certify & Grow Your Business
StickmanCyber can help your business align with the gold standard of information security system management with ISO 27001 certification. Get your systems and processes compliant with StickmanCyber.
A key segment of ISO 27001, which consists of clauses 4 to 10, remained roughly the same, with only minor changes. These clauses still include scope, interested parties, context, information security policy, risk management, resources, training & awareness, communication, document control, monitoring and measurement, internal audit, management review, and corrective actions.
However, the security controls detailed in ISO 27002:2013 Annex A are now updated to 27002:2022 and designed to increase the convenience associated with implementation. For example, the number of controls has decreased from 114 to 93 and are placed in 4 sections instead of the prior 14. There are 11 new controls, while none of the controls were deleted, and many controls were merged.
The new ISO 27002 is significantly longer than the previous version, and the controls themselves have been reordered and updated. Some controls have been merged, and some have been added:
The completely new controls are:
The controls now also have five types of ‘attribute’ to make them easier to categorise:
ISO 27002:2022 was published on February 15, 2022, and ISO 27001:2022 followed on October 25, 2022.
You should implement ISO 27001:2022 (including its 2024 amendment). The transition period for the 2022 update ended on 31 October 2025, and all certifications based on ISO 27001:2013 have expired or been withdrawn, which means that your SOA (Statement of Applicability) must refer to the Annex A controls of ISO 27001:2022. If getting certified is not an urgent need for your company, we suggest you start complying to the standard by implementing the controls where your business has gaps, and then commence the certification requirements.
Your company should implement the clauses and Annex A controls described in the ISO 27001:2022 standard, using ISO 27002:2022 as guidance for implementing them.
As outlined above, the changes to ISO 27001:2013 were moderate, and were mainly regarding the way controls are organised. Therefore they only slightly affected your documentation and not the actual technology implemented.
The main changes to documentation were:
The International Accreditation Forum set a three-year transition period for certified organisations to revise their management system to conform to ISO 27001:2022. That period ended on 31 October 2025, and all certifications based on ISO 27001:2013 expired or were withdrawn at the end of it.
If your organisation did not complete its transition in time, its ISO 27001:2013 certificate is no longer valid, and it will need certification to ISO 27001:2022.
Yes. For certified organisations, the certifying auditor checked that the documentation had been adapted as part of a transition audit, which could take place during a regular surveillance audit, a recertification audit or a separate audit. Your auditor will continue to review your documentation against ISO 27001:2022 during regular surveillance audits.
Whether you are looking to achieve ISO 27001:2022 certification for the first time or need help moving from an expired ISO 27001:2013 certificate, StickmanCyber is here to help. Our consultants are certified as ISO 27001 Lead Auditors and Implementers.
Book a free consultation with one of our experts, to get started on your ISO 27001 journey.
The First Step is Crucial. Start with a Cybersecurity Assessment
Where are you at your cybersecurity maturity journey? Get an assessment of your current security posture and identify the gaps and challenges that you need to act upon. Start an assessment